Forum Discussion
SSL logging impact on f5?
Hello Experts,
I was just curious if there would be any impact on performance of f5 if we enabled SSL logging? I found out hot to do it but I don't want to mess up the entire infrastructure. Please let me know if it will slow the working performance of the f5, affect other VIPs configuration or any error/outage at all.
https://support.f5.com/kb/en-us/solutions/public/15000/200/sol15292.html
Thank you all, you are the best.
R
- Hannes_RappNimbostratus
Hi,
An iRule which logs SSL handshake details to a Remote Syslog server (HSL) would not be a problem. Test in QA first and after a successful test in QA, proceed to PROD by progressively enabling it on more Virtual Servers (don't have to implement for all services at once).
- When using an iRule logging solution, try to avoid on-appliance logging if possible (i.e. /var/log/ltm or /var/log/user.notice). If you need a permanent solution, go for remote logging (HSL).
- If you were thinking about SSL Debug as your logging solution (
), I would not recommend that as your permanent SSL logging solution since it does not qualify for one. Any built-in debug commands are meant to be used for short-term to troubleshooting on-going incidents or problems.tmsh modify /sys db log.ssl.level value Debug
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com